Oracle disclosed a critical vulnerability in Oracle WebCenter Sites that lets a low-privileged attacker with network access take over the product and reach beyond it into other components.
What Is It
CVE-2026-83031 is a vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware, in the WebCenter Sites component itself. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise the product, with no user interaction required. Successful attacks result in full takeover of Oracle WebCenter Sites.
The CVSS 3.1 base score is 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, low privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability. The record was published by Oracle's security alert channel on 2026-09-15 and currently carries NVD status "Received."
Why It Matters
Two details drive the 9.9 score. First, the scope is changed: Oracle states that while the vulnerability lives in WebCenter Sites, attacks may significantly impact additional products. A compromise does not stay contained to the vulnerable component. Second, the bar for exploitation is low; HTTP reachability plus any low-privileged account is enough, which puts internet-facing or broadly accessible WebCenter Sites deployments at real risk.
No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time. That is not a reason to defer patching given the severity and stated ease of exploitation.
What's Vulnerable
Per Oracle, the affected supported versions of Oracle WebCenter Sites are:
- 12.2.1.4.0
- 14.1.2.0.0
No affected CPE entries were listed in the NVD record, and no other products were named as directly vulnerable.
Patch Status
Oracle published this issue through its security alerts program; the associated advisory is the September 2026 Oracle security alert page linked below. No KEV due date or CISA-mandated required action was supplied for this CVE. Administrators should consult the Oracle advisory for the applicable fix and apply it to affected 12.2.1.4.0 and 14.1.2.0.0 deployments.
Sources
- Oracle Security Alert (September 2026), https://www.oracle.com/security-alerts/cspusep2026.html
- NVD, CVE-2026-83031 (source identifier: [email protected]), published 2026-09-15